×
dtu data breach

The Technical University of Denmark (DTU) says information belonging to up to 200,000 users may have been exposed after hackers accessed its identity and access management system and downloaded a large amount of data.

The university says the attacker used compromised credentials to log into DTUBasen, its identity and access management system, allowing access to more than two decades of user data. The breach may affect up to 200,000 current and former users, including students, employees, guests and external partners.

How the breach happened

According to DTU’s disclosure, threat actors compromised DTU profiles and used them to access DTUBasen, which contains personal data dating back to 2003. The university confirmed that it cannot currently determine precisely what information was downloaded or how many people have been affected.

The database holds records of approximately 40,000 active users and around 160,000 former users, all of whom may have been caught up in the incident.

DTU data breach - campus building of the Technical University of Denmark
A campus building of the Technical University of Denmark in Lyngby. DTU’s identity system held data going back to 2003.

What data was potentially exposed

Potentially exposed information for current users includes Danish civil registration numbers (CPR), full names, home addresses and profile pictures, as well as work email addresses, job titles, office locations and other employment-related details.

The dataset also contained the names, relationships and telephone numbers of users’ next of kin, where provided by active users. For former users, home addresses, profile pictures and next-of-kin information are automatically deleted after six months, but DTUBasen retains CPR numbers and full names indefinitely.

DTU warns that cybercriminals could use the exposed CPR numbers and other personal data for identity fraud and to make phishing attacks more convincing.

University response

University Director Bjarke Bak Christensen called it a serious attack on DTU, saying the university deeply regretted the uncertainty it was causing for the people whose information may have been affected. He said the university’s first priority had been to establish the extent of the attack, limit its consequences, and ensure those affected were notified and knew what steps to take.

The university says potentially impacted individuals will be notified through e-Boks, the official digital mailbox system DTU uses for documents and notices to students and staff. However, not all affected people can be contacted directly — so DTU has issued a public notice and is urging people to share it with former employees, students, guests and external partners.

Anyone who has been an employee, student, guest or external partner of DTU since 2003 may be affected.

DTU data breach - illustration of a cyber attack on a laptop
Hackers used compromised credentials to access DTU’s identity system. The university warns of possible identity fraud and phishing.

What affected people should do

DTU is urging anyone connected to the university since 2003 to remain alert for suspicious messages, avoid approving unexpected login requests, and change passwords on any other services where they reused their DTU password. The university also recommends considering a credit alert against the affected CPR number, and cautions against disclosing passwords or sensitive information in replies to unexpected communications.

DTU works with the Danish Armed Forces and the defence industry on drone technology and has a significant defence and security research programme, although there is currently no indication that the attack was connected to this work. The investigation remains ongoing, and the university says it will provide more information as soon as possible.

FAKTA: The DTU data breach

  • Hackers accessed DTU’s identity system, DTUBasen, using compromised credentials and downloaded a large amount of data.
  • Up to 200,000 current and former users may be affected; data goes back to 2003.
  • The database holds around 40,000 active users and 160,000 former users.
  • Exposed data may include CPR numbers, names, addresses, profile photos, work emails and next-of-kin details.
  • DTU will notify most affected people via e-Boks and has issued a public notice for others.
  • Affected people are advised to watch for phishing, change reused passwords and consider a CPR credit alert.

Conclusion

The DTU breach is one of the largest data incidents to hit a Danish educational institution, with highly sensitive CPR numbers among the data at risk. With the university unable to say exactly whose data was taken, vigilance is the main defence for the up to 200,000 people in DTUBasen’s records.

Frequently asked questions

What is DTUBasen?
DTU’s identity and access management system, which stores personal data of current and former employees, students, guests and external partners.

Who may be affected?
Anyone who has been an employee, student, guest or external partner of DTU since 2003 — up to 200,000 people.

What information was exposed?
Potentially CPR numbers, full names, home addresses, profile photos, work emails, job details and some next-of-kin information.

How will I be notified?
Most affected current and former students and employees will be notified directly via e-Boks; DTU has also issued a public notice to reach others.

What should I do?
Be cautious of suspicious messages, change passwords reused from your DTU account, and consider placing a credit alert on your CPR number.

Read more in our Education news section.

Related: Violence Widespread in Danish Schools, New Study Reveals

Leave a Reply

Your email address will not be published. Required fields are marked *

Author

usman2344913@gmail.com

Related Posts

Thursday briefing: Why young people are taking to the streets across France

Tens of thousands of young people and adults have taken to the streets across France to protest the state of the nation’s...

Read out all
Klimamester modtager gyldent trofæ ved udendørs ceremoni

Climate Champions 2026: The People Turning Climate Promises Into Measurable Action

From AGRA's Climate and Productivity Champion award in Kigali to Dane County's 73 climate champions and Ohio's 2026 Clean Energy Champions Awards:...

Read out all
More than 1,000 participants expected at the fifth Climate Change Summit climate event in Bucharest

Bucharest Hosts Fifth Climate Change Summit at the Palace of Parliament on October 14

The fifth Climate Change Summit opens at Bucharest’s Palace of Parliament on 14 October 2026, bringing together more than 1,000 experts, business...

Read out all

South Korea Threatens Legal Action Over Fuel Shipments to Russia

South Korea has announced it will pursue legal action if investigations confirm that fuel shipments from its ports to Russia have violated...

Read out all
Students and a teacher planting a seedling together in a Brussels garden during a climate education event

EU Opens Registration for Education for Climate Day 2026 on Intergenerational Fairness

The EU's Education for Climate Coalition has opened registration for Education for Climate Day 2026 on 22 October, themed on intergenerational fairness...

Read out all

South Sudan Elections Uncertain Amidst Ongoing Challenges

South Sudan faces an uncertain path toward its first general election, scheduled for December 22, as significant logistical and political hurdles persist....

Read out all